Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-30450

Опубликовано: 08 апр. 2023
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which there is a data type mismatch that cannot be automatically fixed by rpk, and instead a user must reconfigure (while a cluster is turned off) in order to have TLS on broker RPC ports. NOTE: the fix was also backported to the 22.2 and 22.3 branches.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redpanda:redpanda:*:*:*:*:*:*:*:*
Версия до 23.1.2 (исключая)

EPSS

Процентиль: 25%
0.00084
Низкий

4.3 Medium

CVSS3

Дефекты

NVD-CWE-Other
CWE-20

Связанные уязвимости

CVSS3: 4.3
github
почти 3 года назад

rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which there is a data type mismatch that cannot be automatically fixed by rpk, and instead a user must reconfigure (while a cluster is turned off) in order to have TLS on broker RPC ports. NOTE: the fix was also backported to the 22.2 and 22.3 branches.

EPSS

Процентиль: 25%
0.00084
Низкий

4.3 Medium

CVSS3

Дефекты

NVD-CWE-Other
CWE-20